Can spammers just setup an auto-responder to defeat TMDA?
In theory yes, but in practice this is not likely to happen. Most SPAM is unrepliable, so TMDA’s confirmation requests are never delivered to them. They use non-valid return addresses as to not incur the cost of the tremendous number of bounces they generate. Using a valid return address to process all the bounces looking for confirmation messages to auto-reply to would defeat their economies of scale. It would also make them easy to block, track down and report, sue, etc.